CVE-2016-2105
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
- Affected products
- Alt Linux, Centos, Cisco Nexus, Cisco Wls, Freebsd, Huawei Vrp, Ibm Aix, Junos
- Redhat Enterprise Linux Desktop
- = 6.0
- Redhat Enterprise Linux Hpc Node
- = 6
- Redhat Enterprise Linux Server
- = 6.0
- Redhat Enterprise Linux Workstation
- = 6.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 39.6% (99th percentile)
- Weakness
- CWE-190
- NVD status
- Modified
- Published
- 2016-05-05
CVE-2016-2105 at NVD
1 known exploit for CVE-2016-2105
Proof-of-concept code and exploit modules indexed by Sploitus